Location: Washington, DC (Federal Client)
Duration: 12+ Months
Minimum Qualifications:
Bachelor's degree in cybersecurity, information systems, computer science, engineering, or a related discipline.
At least 10 years of progressively responsible cybersecurity experience.
At least 7 years of direct ISSO, RMF, security authorization, or federal cybersecurity compliance experience.
At least 3 years of experience leading ISSO personnel or cybersecurity governance activities.
Demonstrated experience supporting FISMA Moderate systems and NIST RMF activities.
Demonstrated experience developing or reviewing SSPs, SAPs, SARs, POA&Ms, continuous monitoring plans, security impact analyses, and assessment evidence.
Experience coordinating with Authorizing Officials, ISSMs, System Owners, assessors, auditors, SOC personnel, privacy personnel, and technical operations teams.
Experience managing deliverable quality, SLAs, KPIs, risks, issues, corrective actions, and audit evidence.
Ability to obtain and maintain Tier 4 High-Risk Public Trust suitability.
United States citizenship.
Preferred Qualifications
CISSP, CGRC/CAP, CISM, CCSP, or comparable senior cybersecurity certification.
PMP or equivalent program/project management certification.
Experience with CSAM or another federal GRC and authorization platform.
Experience with ServiceNow, Splunk, Tenable Nessus or Qualys.
Experience with Microsoft Azure Government, Microsoft 365 GCCC High, Entra ID, Defender, Intune, and BigFix.
Familiarity with Okta, Palo Alto Panorama, Zscaler, Cisco, and Aruba environments.
Experience with FedRAMP inherited controls, Customer Responsibility Matrices, Shared Responsibility Matrices, and cloud authorization packages.
Experience supporting FISMA audits, Inspector General reviews, GAO audits, penetration tests, and independent security control assessments.